Multiple outlets report that a critical vulnerability in the Funnel Builder WordPress plugin is being actively exploited in the wild. The reported activity involves injecting malicious JavaScript into WooCommerce checkout pages. The injected code is designed to capture or redirect payment information, enabling credit card or payment data theft, commonly referred to as checkout skimming.
Sansec has published details about the observed exploitation, and both sources describe the campaign as ongoing rather than a theoretical risk. The issue is said to affect sites that use Funnel Builder in combination with WooCommerce, where checkout pages can be altered to run attacker-supplied scripts.
One source notes that the vulnerability does not currently have an official CVE identifier, suggesting it may not yet be fully standardized in public vulnerability tracking. Overall, the reporting emphasizes the active nature of the attacks, the method of injecting JavaScript into checkout flows, and the targeting of payment data within WooCommerce checkout pages.